CVE-2009-3568
06.10.2009, 20:30
Comment RSS 5.x before 5.x-2.2 and 6.x before 6.x-2.2, a module for Drupal, does not properly enforce permissions when a link is added to the RSS feed, which allows remote attackers to obtain the node title and possibly other sensitive content by reading the feed.Enginsight
Vendor | Product | Version |
---|---|---|
dave_reid | commentrss | 5.x-2.1:x |
dave_reid | commentrss | 6.x-2.1:x |
gabor_hojtsy | commentrss | 5.x-1.0:x |
gabor_hojtsy | commentrss | 5.x-1.1:x |
gabor_hojtsy | commentrss | 5.x-1.2:x |
gabor_hojtsy | commentrss | 5.x-1.x:x |
gabor_hojtsy | commentrss | 5.x-2.0:x |
gabor_hojtsy | commentrss | 5.x-2.x:x |
gabor_hojtsy | commentrss | 6.x-1.0:x |
gabor_hojtsy | commentrss | 6.x-1.1:x |
gabor_hojtsy | commentrss | 6.x-1.2:x |
gabor_hojtsy | commentrss | 6.x-2.0:x |
gabor_hojtsy | commentrss | 6.x-2.x:x |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References